# Install security updates automatically

> Use unattended-upgrades on Ubuntu 24.04 or Debian 12 to install security fixes every day, reboot when needed, and check that it runs.

Source: https://vpsnine.com/help/automatic-security-updates · Updated: 2026-10-09

Most servers that get broken into were running something with a known hole that already had a fix. `unattended-upgrades` installs security updates every day, so the fix lands whether or not you remember to log in that week.

## Switch it on

Ubuntu 24.04 has it installed and enabled already. Debian 12 may not. Running this is safe on either:

```bash
apt update
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
```

Answer `Yes` when it asks about installing stable updates automatically. That writes `/etc/apt/apt.conf.d/20auto-upgrades`:

```text
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";
```

Both `1`s mean daily: refresh the package lists, then install upgrades.

## What it installs

The rules are in `/etc/apt/apt.conf.d/50unattended-upgrades`, under `Allowed-Origins` on Ubuntu or `Origins-Pattern` on Debian. Out of the box:

- Ubuntu installs from `${distro_id}:${distro_codename}-security`, plus Ubuntu Pro's ESM archives if you've attached Pro.
- Debian installs from the security archive (`label=Debian-Security`) and the fixes in Debian's point releases (`label=Debian`).

That's what most servers want. Leave it unless you have a specific reason.

## Rebooting

Kernel and core library updates only take effect after a reboot. You can let unattended-upgrades do that at a quiet hour. Package updates can replace `50unattended-upgrades`, so put your own settings in a file of your own, `/etc/apt/apt.conf.d/52unattended-upgrades-local`:

```text
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
```

The time is in the server's time zone. If a surprise restart would hurt (a long job, a game server with people on it), skip the automatic reboot and do it yourself. On Ubuntu, this file exists when a reboot is waiting:

```bash
ls /var/run/reboot-required && cat /var/run/reboot-required.pkgs
```

## Check it's actually running

A dry run shows what it would install, and complains loudly about config mistakes:

```bash
unattended-upgrade --dry-run --debug
```

Then the timers that kick it off:

```bash
systemctl list-timers apt-daily.timer apt-daily-upgrade.timer
```

Both should be there with a next run time. Give it a day, then read the log:

```bash
tail -n 30 /var/log/unattended-upgrades/unattended-upgrades.log
```

If the log says `dpkg was interrupted`, run `dpkg --configure -a` and then `apt -f install`. If a package keeps getting skipped, it may be held; `apt-mark showhold` lists those. And if the log stays empty for days, check that `20auto-upgrades` has both values at `1` and the timers above are enabled.

## Emails when something's installed

Add this to your local file:

```text
Unattended-Upgrade::Mail "you@example.com";
Unattended-Upgrade::MailReport "on-change";
```

You'll need a working local mail command, like `mailutils`, relaying through a mail service. Outbound port 25 is blocked by default here; [Sending email: port 25](https://vpsnine.com/help/open-port-25) explains why and what to use instead.
